Best Password Managers Compared (2026)
An independent, citation-backed comparison of 10 leading password managers — covering encryption standards, zero-knowledge architecture, third-party security audits, pricing, and platform support. Every figure is linked to its primary source.
Quick verdict
- Best overall: 1Password — strongest audit record, polished apps, reasonable price.
- Best free / open-source: Bitwarden — full-featured free tier, MIT-licensed, Cure53 audited.
- Best self-hosted: KeePass — zero cloud dependency, EU-FOSSA audited, free.
- Avoid if security is paramount: LastPass — 2022 breach exposed encrypted vaults.[4]
Full comparison table
Pricing figures are individual annual plans as of May 2026.[*] All products use zero-knowledge architecture — the vendor cannot access your plaintext vault.
| Product | Encryption | Latest Audit | Open Source | Price/yr | Free Tier | 2FA Methods |
|---|---|---|---|---|---|---|
| 1Password | AES-256-GCM + PBKDF2 | Cure53, Bugcrowd (2024)[1] | No | $35.88[1] | No free tier | TOTP, Duo, hardware keys |
| Bitwarden | AES-256-CBC + PBKDF2/Argon2 | Cure53 (2023)[2] | ✓ Yes | $10.00[2] | Unlimited items, 1 device type | TOTP, YubiKey, Duo, FIDO2 |
| Dashlane | AES-256-CBC + Argon2 | Cure53 (2023)[3] | No | $59.99[3] | 1 device, unlimited items | TOTP, U2F, Duo |
| LastPass | AES-256-CBC + PBKDF2 | Cure53 (2022, pre-breach) (2022)[4] | No | $36.00[4] | 1 device type only | TOTP, YubiKey, Duo |
| Keeper | AES-256-GCM + PBKDF2 | SOC 2 Type 2 (annual) (2024)[5] | No | $34.99[5] | No free tier (30-day trial) | TOTP, YubiKey, DUO, RSA |
| NordPass | XChaCha20 + Argon2 | Cure53 (2023)[6] | No | $35.88[6] | Unlimited items, 1 active session | TOTP, hardware keys |
| RoboForm | AES-256-CBC + PBKDF2 | Secfault Security (2023)[7] | No | $23.88[7] | 1 device, unlimited items | TOTP, SMS (fallback), Microsoft/Google Authenticator |
| Enpass | AES-256-CBC + SQLCipher | Cure53 (2023)[8] | No | $19.99[8] | 25 items, desktop only | TOTP, Authy |
| KeePass | AES-256 / ChaCha20 + Argon2 | European Commission (audit 2016) (2016)[9] | ✓ Yes | Free[9] | Full features, self-hosted | Key file + master password; plugins for TOTP |
| ProtonPass | AES-256-GCM + bcrypt/Argon2 | Cure53 (2023)[10] | ✓ Yes | $23.88[10] | Unlimited logins, 2 vaults | TOTP, Proton 2FA |
How we evaluate password managers
Our full methodology covers scoring rubrics, source tiers, the recency policy, COI disclosure, and the correction process. No vendor paid to appear in or influence this guide.
Read the methodology →Sources
- 1Password (AgileBits). 1Password security model; 1Password audit reports; 1Password pricing Accessed May 2026.
- Bitwarden (Bitwarden Inc.). Bitwarden security whitepaper; Bitwarden Cure53 audit 2023; Bitwarden pricing Accessed May 2026.
- Dashlane (Dashlane SAS). Dashlane security architecture; Dashlane pricing Accessed May 2026.
- LastPass (GoTo Technologies). LastPass security incident notice (2022); LastPass pricing Accessed May 2026.
- Keeper (Keeper Security). Keeper security documentation; Keeper pricing Accessed May 2026.
- NordPass (Nord Security). NordPass security; NordPass pricing Accessed May 2026.
- RoboForm (Siber Systems). RoboForm security overview; RoboForm pricing Accessed May 2026.
- Enpass (Sinew Software). Enpass security; Enpass pricing Accessed May 2026.
- KeePass (Dominik Reichl (open source)). KeePass official site; EU-FOSSA KeePass audit report (2016) Accessed May 2026.
- ProtonPass (Proton AG). ProtonPass security details; ProtonPass Cure53 audit 2023; ProtonPass pricing Accessed May 2026.
- * Prices are listed annual individual plan rates in USD as published on vendor pricing pages, accessed May 2026. Prices may vary by region and change without notice.